question on email header from and reply-to

Janus Bariñan 1,126 Reputation points
2021-01-11T16:01:42.183+00:00

Hi,

Just like to understand about the email header particularly the From and Reply-To section.

First Question:
I received an email coming from this [sample email address and names]
From: Joe Satriani <******@gotowebinar.com>
Reply-To: ******@serviceit.com

Does this mean that gotowebinar.com mail servers is sending in behalf of serviceit.com domain? And when I reply to that email Joe Satriani <****@gotowebinar.com>** it will be forwarded to ******@serviceit.com ?

Second Question:
I received an email that goes like this:
From: 'Ahmed G' via SPECIAL GROUP <******@mydomain.com>
Reply-To: ******@ahmeddomain.com

How was it that the From field is using my specialgroup distro list? I did not allow Ahmed and other external domains from using our mail servers as sender on behalf of our domain. It's not just that but other external domains as well we see in the reply-to field but using our distro in the From field.

Can anybody shed light?

Thanks!

Exchange Online
Exchange Online
A Microsoft email and calendaring hosted service.
6,171 questions
Outlook Windows Classic Outlook for Windows For business
Microsoft Security Microsoft Graph
{count} votes

Accepted answer
  1. Janus Bariñan 1,126 Reputation points
    2021-01-14T09:07:21.94+00:00

    I found out now why it is so. This applies if DMARC policy has p=reject or p=quarantine. The receiver's delivery system will allow the use of via so not to trigger the DMARC policy of the sender thus delivering the mail successfully.


1 additional answer

Sort by: Most helpful
  1. Kael Yao 37,746 Reputation points Moderator
    2021-01-13T02:55:02.42+00:00

    @Janus Bariñan
    Hi,

    First Question:
    To my knowledge,the Reply-to email address can be modified via many email clients when sending emails.

    Let's take Outlook for example:
    When you are going to use email address (******@Domain-A.com for example) to send a new email, you can configure the Reply-to address to be ******@Domain-B.com like in the following screenshot:
    55874-75.png
    In this case, when the recipient replies to the email, only the ******@Domain-B.com will get the reply email, while the ******@Domain-A.com won't.

    And in your case, if you reply to the email, only @serviceit.com will get your response.
    Unless there are some forwarding rules or settings to forward the email to Joe Satriani <
    @gotowebinar.com> in their environment.

    I think it is maybe because Joe Satriani <******@gotowebinar.com> set the Reply-to address himself when sending the email.
    Or it may also be someone hacked the sender's account and changed the Reply-to address to send the spoofed emails which you need to pay attention to.

    Second Question:
    I think it should be Email spoofing.
    Have you configured SPF,DKIM or DMARC records for your email domain?
    If haven't yet, please take it into consideration for security.
    Here is an article on this topic for your reference: Office 365: Using SPF, DKIM and DMARC for Secure Messaging


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.